<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyberwart</title>
	<atom:link href="http://www.cyberwart.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyberwart.com/blog</link>
	<description>Cyber Warfare Technologies</description>
	<lastBuildDate>Tue, 09 Mar 2010 22:36:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hello Koko</title>
		<link>http://www.cyberwart.com/blog/2010/03/09/hello-koko/</link>
		<comments>http://www.cyberwart.com/blog/2010/03/09/hello-koko/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 21:46:23 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/03/09/hello-koko/</guid>
		<description><![CDATA[Today an in-house tool I&#8217;ve been developing (Dragonslayer) triggered on events matching both a PDF signature and traffic to hosts on the MalwareDomainList. In particular it was hitting on ip 79.171.22.190 which is hosted as kokojamba.com.
The host is registered as follows:
Domain Whois record

Queried whois.internic.net with &#8220;dom kokojamba.com&#8221;&#8230;

Domain name: kokojamba.com

Status: Active

Registrant:

Name: Andrzej Ignashevitch

Address: Pulawska, 15

City: Warszawa

Province/state: [...]]]></description>
			<content:encoded><![CDATA[<p>Today an in-house tool I&#8217;ve been developing (Dragonslayer) triggered on events matching both a PDF signature and traffic to hosts on the <a href="http://www.malwaredomainlist.com">MalwareDomainList</a>. In particular it was hitting on ip <a href="http://www.malwaredomainlist.com/mdl.php?search=79.171.22.190">79.171.22.190</a> which is hosted as kokojamba.com.</p>
<p>The host is registered as follows:</p>
<p><span style="font-family: Times New Roman; font-size: 13pt;"><strong>Domain Whois record<br />
</strong></span></p>
<p><span style="font-family: Times New Roman; font-size: 12pt;">Queried whois.internic.net with &#8220;dom kokojamba.com&#8221;&#8230;<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Domain name: kokojamba.com<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Status: Active<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Registrant:<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Name: Andrzej Ignashevitch<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Address: Pulawska, 15<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">City: Warszawa<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Province/state: poland<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Country: PL<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Postal Code: PL-02515<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Administrative Contact:<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Name: Andrzej Ignashevitch<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Organization: Andrzej Ignashevitch<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Address: Pulawska, 15<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">City: Warszawa<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Province/state: poland<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Country: PL<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Postal Code: PL-02515<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Phone: <img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko1.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko2.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko3.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko4.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko5.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko6.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko7.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko8.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko9.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko10.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko11.png" alt="" /><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko12.png" alt="" />+48.713965232<img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko13.png" alt="" /><br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Fax: +48.713965232<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Email: magikmind13@gmail.com<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Technical Contact:<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Name: Andrzej Ignashevitch<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Organization: Andrzej Ignashevitch<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Address: Pulawska, 15<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">City: Warszawa<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Province/state: poland<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Country: PL<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Postal Code: PL-02515<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Nameserver Information:<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;"> ns1.kokojamba.com<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;"> ns2.kokojamba.com<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Create: 2010-03-04 20:05:36<br />
</span></p>
<p><span style="font-family: Courier New; font-size: 10pt;">Update: 2010-03-04<br />
</span></p>
<p>The admin panel had the default user/password of &#8220;admin&#8221;:&#8221;admin&#8221;.</p>
<p>Here&#8217;s what&#8217;s on the inside:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko14.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko15.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko16.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko17.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko18.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/03/030910_2145_HelloKoko19.png" alt="" /></p>
<p>I wrote a quick python script to download all the compromised host data. It&#8217;s available here: <a href="http://www.cyberwart.com/files/koko.txt.gz">http://www.cyberwart.com/files/koko.txt.gz</a> I&#8217;m not sure if each IP is compromised or only downloaded a (one or more payloads). It doesn&#8217;t appear that simply visiting the site gets you one the list. Also, the files downloaded feature seems broken as I&#8217;ve seen payloads delivered but not showing up on the list.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/03/09/hello-koko/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can you believe that hot blond on Facebook wasn’t just desperate to meet me?!</title>
		<link>http://www.cyberwart.com/blog/2010/02/14/can-you-believe-that-hot-blond-on-facebook-wasn%e2%80%99t-just-desperate-to-meet-me/</link>
		<comments>http://www.cyberwart.com/blog/2010/02/14/can-you-believe-that-hot-blond-on-facebook-wasn%e2%80%99t-just-desperate-to-meet-me/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 06:57:51 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/02/14/can-you-believe-that-hot-blond-on-facebook-wasn%e2%80%99t-just-desperate-to-meet-me/</guid>
		<description><![CDATA[So a hot blond decided to randomly add me on Facebook. I know what you&#8217;re thinking: &#8220;Matt with your dashing good looks, charm, and terrific fashion sense, I&#8217;m sure you have models contacting you all the time&#8221;. I won&#8217;t argue with your logic, but in my boredom I decided to investigate a little. Here&#8217;s what [...]]]></description>
			<content:encoded><![CDATA[<p>So a hot blond decided to randomly add me on Facebook. I know what you&#8217;re thinking: &#8220;Matt with your dashing good looks, charm, and terrific fashion sense, I&#8217;m sure you have models contacting you all the time&#8221;. I won&#8217;t argue with your logic, but in my boredom I decided to investigate a little. Here&#8217;s what I found:
</p>
<p>
 </p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie1.png" alt=""/>
	</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie2.png" alt=""/>
	</p>
<p>
 </p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie3.png" alt=""/>
	</p>
<p>
 </p>
<p>
 </p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie4.png" alt=""/>
	</p>
<p>
 </p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie5.png" alt=""/>
	</p>
<p>
 </p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie6.png" alt=""/>
	</p>
<p>
 </p>
<p>If you think this isn&#8217;t normal there&#8217;s a job req up on fling:
</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0657_Canyoubelie7.png" alt=""/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/02/14/can-you-believe-that-hot-blond-on-facebook-wasn%e2%80%99t-just-desperate-to-meet-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trying to get my FIOS Bill</title>
		<link>http://www.cyberwart.com/blog/2010/02/14/trying-to-get-my-fios-bill/</link>
		<comments>http://www.cyberwart.com/blog/2010/02/14/trying-to-get-my-fios-bill/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 06:16:19 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/02/14/trying-to-get-my-fios-bill/</guid>
		<description><![CDATA[For weeks I&#8217;ve been trying to get my Verizon FIOS bill. Verizon happily debits my credit card every month but I need the receipts. I&#8217;ve logged into my account online and all I get is the below message saying the system isn&#8217;t working:


	
I emailed them and got no help:


	
Note: I LOVE automated completely useless responses. [...]]]></description>
			<content:encoded><![CDATA[<p>For weeks I&#8217;ve been trying to get my Verizon FIOS bill. Verizon happily debits my credit card every month but I need the receipts. I&#8217;ve logged into my account online and all I get is the below message saying the system isn&#8217;t working:
</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0615_Tryingtoget1.png" alt=""/>
	</p>
<p>I emailed them and got no help:
</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0615_Tryingtoget2.png" alt=""/>
	</p>
<p><em>Note: I LOVE automated completely useless responses. </em>
	</p>
<p>Verizon decided to step up their incompetence when I tried to access my billing info yet again tonight:
</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/02/021410_0615_Tryingtoget3.png" alt=""/>
	</p>
<p>So at this point, I guess I get to spend hours on hold waiting for them. Oh how I love incompetent multinational companies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/02/14/trying-to-get-my-fios-bill/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Hex-Rays</title>
		<link>http://www.cyberwart.com/blog/2010/02/01/new-hex-rays/</link>
		<comments>http://www.cyberwart.com/blog/2010/02/01/new-hex-rays/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 15:13:47 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/02/01/new-hex-rays/</guid>
		<description><![CDATA[A new version of Hex-Rays is out today. Combined with my eval copy of Binnavi today is just a good day!
]]></description>
			<content:encoded><![CDATA[<p>A new version of Hex-Rays is out today. Combined with my eval copy of Binnavi today is just a good day!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/02/01/new-hex-rays/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>16 byte CRC is Common</title>
		<link>http://www.cyberwart.com/blog/2010/02/01/16-byte-crc-is-common/</link>
		<comments>http://www.cyberwart.com/blog/2010/02/01/16-byte-crc-is-common/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 15:13:11 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/02/01/16-byte-crc-is-common/</guid>
		<description><![CDATA[Saw this: http://www.theregister.co.uk/2010/01/26/aurora_attack_origins/
The link argues that the unusual CRC in Aurora that uses 16 unsigned ints isn&#8217;t actually that uncommon&#8230; in fact it&#8217;s in a lot of EE type text books.
]]></description>
			<content:encoded><![CDATA[<p>Saw this: http://www.theregister.co.uk/2010/01/26/aurora_attack_origins/</p>
<p>The link argues that the unusual CRC in Aurora that uses 16 unsigned ints isn&#8217;t actually that uncommon&#8230; in fact it&#8217;s in a lot of EE type text books.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/02/01/16-byte-crc-is-common/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Laptopantivirus.microsoft.com</title>
		<link>http://www.cyberwart.com/blog/2010/01/27/laptopantivirus-microsoft-com/</link>
		<comments>http://www.cyberwart.com/blog/2010/01/27/laptopantivirus-microsoft-com/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 18:04:20 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=452</guid>
		<description><![CDATA[This find is due to Sara. A quick check in the traffic logs for a host sent to the help desk showed a bit odd network traffic. We saw the computer polling laptopantivirus.microsoft.com/block.php. Looking quickly you think, well that&#8217;s Microsoft &#8211; it&#8217;s okay! Well, Microsoft using PHP? That&#8217;s not overly likely and the &#8220;laptopantivirus&#8221; part [...]]]></description>
			<content:encoded><![CDATA[<p>This find is due to Sara. A quick check in the traffic logs for a host sent to the help desk showed a bit odd network traffic. We saw the computer polling laptopantivirus.microsoft.com/block.php. Looking quickly you think, well that&#8217;s Microsoft &#8211; it&#8217;s okay! Well, Microsoft using PHP? That&#8217;s not overly likely and the &#8220;laptopantivirus&#8221; part seems sketchy. If you look at the IP address it&#8217;s 195.88.190.54 &#8211; Registered to Bigness Group based in Russia.</p>
<p>See below</p>
<p><a rel="attachment wp-att-453" href="http://www.cyberwart.com/blog/2010/01/27/laptopantivirus-microsoft-com/1-27-2010-12-35-05-pm/"><img class="aligncenter size-full wp-image-453" title="1-27-2010 12-35-05 PM" src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/1-27-2010-12-35-05-PM-e1264615340785.png" alt="" width="400" height="244" /></a></p>
<p><a rel="attachment wp-att-454" href="http://www.cyberwart.com/blog/2010/01/27/laptopantivirus-microsoft-com/1-27-2010-12-56-45-pm/"><img class="aligncenter size-full wp-image-454" title="1-27-2010 12-56-45 PM" src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/1-27-2010-12-56-45-PM.png" alt="" width="523" height="842" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/01/27/laptopantivirus-microsoft-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DoH!</title>
		<link>http://www.cyberwart.com/blog/2010/01/25/doh/</link>
		<comments>http://www.cyberwart.com/blog/2010/01/25/doh/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 15:52:24 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/01/25/doh/</guid>
		<description><![CDATA[DoH! is meeting THIS WEDS Jan 27th at 7pm! Again at GWU/Foggy Bottom.
]]></description>
			<content:encoded><![CDATA[<p>DoH! is meeting THIS WEDS Jan 27th at 7pm! Again at GWU/Foggy Bottom.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/01/25/doh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The CON: Real Slim Snipa</title>
		<link>http://www.cyberwart.com/blog/2010/01/20/the-con-real-slim-snipa/</link>
		<comments>http://www.cyberwart.com/blog/2010/01/20/the-con-real-slim-snipa/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 00:20:03 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/01/20/the-con-real-slim-snipa/</guid>
		<description><![CDATA[Greetz &#8220;Tu Snipa&#8221;. Adam, great blog entry: http://www.thecoverofnight.com/blog/?p=214
]]></description>
			<content:encoded><![CDATA[<p>Greetz &#8220;Tu Snipa&#8221;. Adam, great blog entry: http://www.thecoverofnight.com/blog/?p=214</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/01/20/the-con-real-slim-snipa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Evidence from Secureworks</title>
		<link>http://www.cyberwart.com/blog/2010/01/20/new-evidence-from-secureworks/</link>
		<comments>http://www.cyberwart.com/blog/2010/01/20/new-evidence-from-secureworks/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 00:17:58 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/01/20/new-evidence-from-secureworks/</guid>
		<description><![CDATA[Great link here: http://www.secureworks.com/research/blog/index.php/2010/01/20/operation-aurora-clues-in-the-code/
Basically they found a CRC algorithm in the binary that Googling appears to indicate is used only in Chinese language forums. Very nice hard data point. 
]]></description>
			<content:encoded><![CDATA[<p>Great link here: http://www.secureworks.com/research/blog/index.php/2010/01/20/operation-aurora-clues-in-the-code/</p>
<p>Basically they found a CRC algorithm in the binary that Googling appears to indicate is used only in Chinese language forums. Very nice hard data point. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/01/20/new-evidence-from-secureworks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Idle Speculation on Auroras</title>
		<link>http://www.cyberwart.com/blog/2010/01/19/idle-speculation-on-auroras/</link>
		<comments>http://www.cyberwart.com/blog/2010/01/19/idle-speculation-on-auroras/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 20:55:56 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/01/19/idle-speculation-on-auroras/</guid>
		<description><![CDATA[Now that the Symantec write up seems legit here&#8217;s a little background digging I did the other day on the domains. I think this sort of information is mainly idle speculation, but rather than simply presenting opinions I&#8217;m going to provide screenshots. This is based on looking up network information for the domains listed by [...]]]></description>
			<content:encoded><![CDATA[<p>Now that the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2010-011114-1830-99&amp;tabid=2">Symantec write up</a> seems legit here&#8217;s a little background digging I did the other day on the domains. I think this sort of information is mainly idle speculation, but rather than simply presenting opinions I&#8217;m going to provide screenshots. This is based on looking up network information for the domains listed by Symantic, namely:</p>
<ul>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">yahooo.8866.org<br />
</span></li>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">sl1.homelinux.org<br />
</span></li>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">360.homeunix.com<br />
</span></li>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">li107-40.members.linode.com<br />
</span></li>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">ftp2.homeunix.com<br />
</span></li>
<li><span style="color: #333333; font-family: Verdana; font-size: 9pt;">update.ourhobby.com<br />
</span></li>
</ul>
<p>Here&#8217;s what I saw:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula1.png" alt="" /></p>
<p>Interestingly here, the first hostname is in <strong>Korea</strong> – not China. If you want to ping up the admin the info is listed as:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula2.png" alt="" /></p>
<p>Another domain sl1.homelinux.org is again shared hosted, and it has multiple domains including those associated with Russia:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula3.png" alt="" /></p>
<p>Another hostname 360.homeunix.com has a little more info. The hostname is set to localhost, but the domain appears to be in the US:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula4.png" alt="" /></p>
<p>Same with update.ourhobby.com</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula5.png" alt="" /></p>
<p>Though in fairness it appears to be only a US based service:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula6.png" alt="" /></p>
<p>Li170-40.members.linode.com actually had some info:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula7.png" alt="" /></p>
<p>If you look above you see the IP is US based with US based points of contact &#8211; though one appears to be Canadian as well.</p>
<p>yahoo.8866.org,  finally this one appears to be in China</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/011910_2055_IdleSpecula8.png" alt="" /></p>
<p>A lot of the speculation is based on IP addresses and where they resolve to. I believe this is a poor way to do analysis. If I were a criminal or a nation state, I would certainly own a lot of 3<sup>rd</sup> party easy hosts and create a very complex path that would be near impossible to establish my true identity. I don&#8217;t believe the Chinese would be easily attributed back to Chinese IP addresses. Additionally, if you look at the above, it&#8217;s not entirely clear that China is the sole source. There are Chinese, Korean, and US hosts/domains. This might provide things to think about as others are speculating about attribution based on where the malware connects back to.</p>
<p>UPDATE:</p>
<p>Saw this link associated with the email address (ppyy@bentium.com): http://archives.neohapsis.com/archives/postfix/2001-05/1841.html. Further if you look up the  domain 8866.com you see things like: http://google.com/safebrowsing/diagnostic?site=8866.org/</p>
<p>The more I see the more it looks like a regular malware domain. Maybe &#8220;the real badguys&#8221; hacked 8866.com to then hack google and those 36 other companies, but if I wanted to say off the radar at all this seems like a really bad idea. I&#8217;m thinking regular malware.</p>
<p>All screenshots are from <a href="http://www.centralops.net">www.centralops.net</a> or <a href="http://www.robtex.com">www.robtex.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/01/19/idle-speculation-on-auroras/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
